Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0006 ✕ technique: T1555 ✕
Download CSV Show ATT&CK heatmapUnusual access to the AD Sync credential files Informational Cloud 2 variations
The AD Sync credential files were accessed in an unusual way.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Credential Access (TA0006)ATT&CK techniques: Credentials from Password Stores (T1555)Required data: XDR Agent with eXtended Threat Hunting (XTH)Attacker's goals: Extracting and decrypting stored Azure AD and Active Directory credentials from Azure AD Connect servers.Investigative actions: See whether this was a legitimate action. Follow the causality chain/user/host activities. Follow unusual actions of the AD Sync user. Check for remote SMB connections to the agent. Check for unusual Azure AD authentications. Check if this happened on other endpoints. Check for unusual logins.Variations
Suspicious process access to the AD Sync credential files
Medium overridden
The AD Sync credential files were accessed in an unusual way. overridden
An abnormal process accessed the AD Sync credential files
Low overridden
The AD Sync credential files were accessed in an unusual way. overridden